OpenDocumentsBLOCK
Self-hosted RAG platform for AI document search across GitHub, Notion, Google Drive, local files, and web sources with citations.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
OpenDocuments Self-hosted RAG platform for AI document search across GitHub, Notion, Google Drive, Confluence, S3, local files, and web sources
English | 한국어
What is OpenDocuments?
OpenDocuments is an open source, self-hosted RAG (Retrieval-Augmented Generation) platform that turns scattered company documents into an AI-searchable knowledge base. It connects to sources like GitHub, Notion, Google Drive, Confluence, S3, Swagger/OpenAPI, local files, and web pages, indexes them with hybrid vector + keyword search, and answers natural-language questions with cited sources.
Use OpenDocuments when you want:
- A self-hosted alternative to enterprise AI search and proprietary knowledge-base search tools
- AI document search with citations f
c8a151c2afedOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add opendocuments-parser-xlsx --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env AWS_ACCESS_KEY_ID=${AWS_ACCESS_KEY_ID} --env AWS_SECRET_ACCESS_KEY=${AWS_SECRET_ACCESS_KEY} --env AWS_SESSION_TOKEN=${AWS_SESSION_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"opendocuments-parser-xlsx": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"AWS_ACCESS_KEY_ID": "${AWS_ACCESS_KEY_ID}",
"AWS_SECRET_ACCESS_KEY": "${AWS_SECRET_ACCESS_KEY}",
"AWS_SESSION_TOKEN": "${AWS_SESSION_TOKEN}"
}
}
}
}Exposed tools (20)
13 read · 5 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Policies | read | Operational policies |
opendocuments_ask | read | Query the RAG engine with a natural language question and get an answer with sources |
opendocuments_config_get | read | Get configuration value |
opendocuments_config_set | write | Set a config value (note: edit opendocuments.config.ts directly) |
opendocuments_connector_list | write | List registered connectors and their sync status |
opendocuments_connector_sync | write | Sync a connector to discover and index new documents |
opendocuments_doctor | write | Run a health check on the OpenDocuments system and report status of all components |
opendocuments_document_delete | destructive | Delete a document (soft) |
opendocuments_document_get | read | Get document details by ID |
opendocuments_document_list | read | List all indexed documents in the document store |
opendocuments_document_reindex | read | Reindex a document |
opendocuments_index_path | read | Index a local file or directory into the document store |
opendocuments_index_status | read | Get indexing status |
opendocuments_plugin_add | write | Install a plugin |
opendocuments_plugin_list | read | List installed plugins |
opendocuments_plugin_remove | destructive | Remove a plugin |
opendocuments_search | read | Perform a vector similarity search without LLM generation, returning raw document chunks |
opendocuments_stats | read | Get system statistics including document count, workspace count, and plugin info |
opendocuments_workspace_list | read | List workspaces |
opendocuments_workspace_switch | read | Switch workspace |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (8 observation(s))
- Shell
- declared (6 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (18)
exec(sql: string): void
exec(sql: string): void {if (origin.startsWith('http://localhost:') || origin.startsWith('http://127.0.0.1:')) {opendocuments_document_delete, opendocuments_plugin_remove
const packagedPath = resolve(thisDir, '../../web-dist')
const relativePath = resolve(thisDir, '../../../web/dist')
import { createBackup, restoreBackup } from '../../src/commands/backup.js'import { prepareIndexReset } from '../../src/commands/reset-index.js'import type { ModelPlugin } from '../../src/plugin/interfaces.js'proxy_pass http://127.0.0.1:3000;
vitepress
@changesets/cli, turbo, typescript
@hono/node-server, @inquirer/prompts, @opendocuments/connector-confluence, @opendocuments/connector-gdrive, @opendocuments/connector-github, @opendocuments/connector-notion, @opendocuments/connector-s
typescript, vitest
@lancedb/lancedb, better-sqlite3, chalk, eventemitter3, jiti, js-tiktoken, semver, zod
1. The admin UI sends repository, branch, token, path filters, and sync interval to the server.
- API keys and secrets are read from environment variables, not hardcoded.
- [ ] Add failing tests that verify read-only team API keys cannot upload, delete, restore, or share conversations.
Gates applied: no_behavioural_pass.
c8a151c2afedfull audit observations/trust-audit/mcp-server/joungminsung__opendocuments.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | c8a151c2afed | BLOCK | D | 69 | first audit |
Questions
What is the OpenDocuments MCP server?
Self-hosted RAG platform for AI document search across GitHub, Notion, Google Drive, local files, and web sources with citations.
What tools does OpenDocuments expose?
20 in total: 13 read-only, 5 that write, and 2 that can delete or overwrite (opendocuments_document_delete, opendocuments_plugin_remove). Every one is listed on this page with its risk.
Is OpenDocuments safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does OpenDocuments need?
It reads ANTHROPIC_API_KEY, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, CONFLUENCE_TOKEN, GDRIVE_ACCESS_TOKEN, GITHUB_TOKEN, GOOGLE_ACCESS_TOKEN, GOOGLE_API_KEY, NOTION_TOKEN, OPENAI_API_KEY and OPENDOCUMENTS_MODEL_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does OpenDocuments run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as opendocuments-parser-xlsx at 0.1.1.
How current is this page?
The grade is for one exact copy of the source (c8a151c2afed), read on 2026-10-07. The repository is watched and re-audited when it changes.